Http4s 是用于 HTTP 服务的 Scala 接口。在 0.23.35 和 1.0.0-M47 之前,Ember HTTP/1.1 实现不会拒绝同时包含 和 头部的消息,导致中间代理服务器和 Ember 可能采用不同的请求体分帧规则。当 ember-server 位于一个启用 keep-alive 的中间代理之后,且该代理同时转发了这两个头部并基于 进行分帧时,未经身份验证的攻击者可以实施“请求走私”(Request Smuggling):向服务器发送一个第二请求,从而绕过中间代理的访问控制、污染缓存,或者使
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-69217 | 8.7 HIGH | Http4s: Ember Server accepts duplicate Content-Length headers |
| CVE-2026-69205 | 8.7 HIGH | Http4s: Ember Transfer-Encoding value parsing (TE.CL / TE.0 request smuggling) |
| CVE-2026-88975 | 7.5 HIGH | Http4s: Ember HTTP/2 buffers a frame's declared payload before checking SETTINGS_MAX_FRAME |
| CVE-2026-69208 | 7.5 HIGH | Http4s: DigestAuth nonce map grows unbounded |
| CVE-2026-69202 | 7.5 HIGH | Http4s Ember HTTP/2: unbounded inbound body buffering |
| CVE-2026-69218 | 7.5 HIGH | Http4s Ember HTTP/2: unbounded continuation frame accumulation |
| CVE-2026-69210 | 7.5 HIGH | Http4s: WebSocket decoder accepts negative length, causing infinite decode loop |
| CVE-2026-69213 | 7.5 HIGH | Http4s Ember HTTP/2: unbounded outbound frame queue |
| CVE-2026-69203 | 7.5 HIGH | Http4s Ember HTTP/2: does not enforce SETTINGS_MAX_CONCURRENT_STREAMS |
| CVE-2026-69209 | 7.5 HIGH | Http4s: WebSocket decoder accepts unbounded message sizes |
| CVE-2026-69214 | 6.8 MEDIUM | Http4s: CookieJar middleware accepts arbitrary Set-Cookie domain |
| CVE-2026-69215 | 6.8 MEDIUM | Http4s: CookieJar middleware matches by substring, leaking cookies cross-origin |
| CVE-2026-69201 | 5.9 MEDIUM | Http4s: ResourceService and Webjar Service path escape via percent-encoded separators |
| CVE-2026-69212 | 5.9 MEDIUM | Http4s: FollowRedirect middleware leaks credentials over https->http same-authority redire |
| CVE-2026-69206 | 5.9 MEDIUM | Http4s: DigestAuth allows replay of captured requests |
| CVE-2026-69216 | 5.4 MEDIUM | Http4s: Ember chunk parser lenience (TE.TE request smuggling) |
| CVE-2026-69211 | 4.8 MEDIUM | Http4s: Set-Cookie rendering does not escape attribute delimiters |
No comments yet